The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow
Published Jul 14, 2004 ·Due Mar 24, 2022
7.8
HIGHCVSS 3.1
EPSS 7.21%
Description
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
Affected products
No data.
- 2.2
- n/a
- n/a
- n/a
- 4.0
- 4.0
- 4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
Mar 3, 2022
Patch Due
Mar 24, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 7.21% (0.07214) | 94.14th | v5 (v2026.06.15) |
| Jun 22, 2026 | 7.61% (0.07606) | 93.77th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.74% (0.05739) | 92.05th | v5 (v2026.06.15) |
| Apr 17, 2026 | 6.79% (0.06788) | 91.34th | v4 (v2025.03.14) |
| Mar 19, 2026 | 5.12% (0.05116) | 89.74th | v4 (v2025.03.14) |
| Jan 11, 2026 | 3.67% (0.03667) | 87.53th | v4 (v2025.03.14) |
| Dec 26, 2025 | 2.52% (0.02519) | 85.00th | v4 (v2025.03.14) |
| Oct 22, 2025 | 4.23% (0.04226) | 88.22th | v4 (v2025.03.14) |
| Aug 16, 2025 | 5.29% (0.05286) | 89.63th | v4 (v2025.03.14) |
| Jun 8, 2025 | 6.33% (0.06330) | 90.47th | v4 (v2025.03.14) |
| Jun 1, 2025 | 5.31% (0.05312) | 89.58th | v4 (v2025.03.14) |
| May 1, 2025 | 7.19% (0.07190) | 91.12th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.56% (0.10564) | 92.57th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.01% (0.06008) | 84.08th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.96% (0.10958) | 92.88th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.19% (0.00195) | 58.41th | v3 (v2023.03.01) |
| Jul 17, 2024 | 0.26% (0.00262) | 66.32th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.40% (0.00395) | 72.73th | v3 (v2023.03.01) |
| Jan 20, 2024 | 0.40% (0.00395) | 70.72th | v3 (v2023.03.01) |
| Jun 21, 2023 | 0.12% (0.00121) | 45.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00056) | 21.52th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.46% (0.04459) | 88.29th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.46% (0.04459) | 87.13th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.46% (0.04459) | 70.93th | v2 (v2022.01.01) |
References (7)
- http://www.kb.cert.org/vuls/id/647436 third-party-advisoryx_refsource_CERT-VNPatchThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.html third-party-advisoryx_refsource_CERTBroken LinkPatchThird Party AdvisoryUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16590 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-0210 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://www.kb.cert.org/vuls/id/647436 | third-party-advisoryx_refsource_CERT-VNPatchThird Party AdvisoryUS Government Resource | |
| http://www.us-cert.gov/cas/techalerts/TA04-196A.html | third-party-advisoryx_refsource_CERTBroken LinkPatchThird Party AdvisoryUS Government Resource | |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020 | vendor-advisoryx_refsource_MSPatchVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/16590 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166 | vdb-entrysignaturex_refsource_OVALBroken Link | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847 | vdb-entrysignaturex_refsource_OVALBroken Link | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-0210 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.